WordPress: Don't permanently save comment IP
WordPress maintains a separate field for the IP address of the comment author in comments. If you don't need it for your own purposes, you shouldn't simply accept storage as an unchangeable basic property.
Requirements
Check beforehand whether moderation, spam filters or blacklists actually need the comment IP.
Comment IP is its own data field
The WordPress data structure knows comment_author_IP. Plugins, themes and moderation tools can evaluate this field. That's why it's not enough to just check analytics and web server logs.
Minimize before saving
WordPress provides filters for comment data. A data-saving adjustment should remove the IP before the permanent database entry or reduce it to a non-personal value, unless a mandatory function depends on it.
Check
Spam filters, blacklists and moderation plugins can use the comment IP. After making the change, create test comments and check the database, moderation view and spam filter.
Spam protection
If comment spam needs to be prevented, first use local procedures and Antispam Bee to save data check without permanently saving the comment IP.
Dismantling
If a moderation or blocking function absolutely requires the comment IP, only specifically reactivate the previous storage and then limit storage and access again.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
- WordPress Developer: wp_insert_comment
- WordPress Developer: preprocess_comment
- WordPress database description
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.